Skip to content

Add RoboTwin 2.0 BYOF acceptance workflow - #451

Draft
timothy-le7 wants to merge 26 commits into
mainfrom
codex/top5-robotwin
Draft

Add RoboTwin 2.0 BYOF acceptance workflow#451
timothy-le7 wants to merge 26 commits into
mainfrom
codex/top5-robotwin

Conversation

@timothy-le7

@timothy-le7 timothy-le7 commented Sep 11, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Adds a solution-specific RoboTwin 2.0 BYOF registry candidate and a valid, planned npa.workflow/v0.0.1 spec.
  • Pins RoboTwin source RoboTwin-Platform/RoboTwin@96c1feab536306b50c26af200044fcdf126e8904, its XPolicyLab submodule c37109c500be67d0dea6b36bf7337bbd26e763cd, RoboTwin2.0 assets TianxingChen/RoboTwin2.0@785feb15aa4a4f532395ad2b1d2be5f28cb561ad, and CuRobo v0.7.8 source NVlabs/curobo@d64c4b005459db10c5dd867d8b30a87d5bda9bdb without silently upgrading any component.
  • Closes the public, immutable Ubuntu/APT side of a neutral zero-vendor-payload bootstrap. The candidate is still deliberately unbuilt, retains the 2.0-curobo-v0.7.8-rtfetch-unbuilt version, is absent from accepted/public release inventories, and remains publication-quarantined.
  • Records the candidate in the Blackwell inventory only as verdict: unknown and validation: pending-build, with matching not-routed/not-validated documentation.
  • Keeps normal submit, direct BYOF/script entrypoints, runtime delivery, and the image scanner fail closed until all independent legal, authorization, content-policy, build, byte, and live gates are satisfied.

This PR remains a draft. It does not claim a built or pullable image, runtime/source/asset delivery, simulator success, generated output, public availability, or supported release.

Capability and workflow contract

The deferred hard-gate capability is beat_block_hammer_successful_seed_replay_collection. A separately authorized live run must use the official beat_block_hammer bimanual task with the demo_clean data-collection configuration, discover and replay an actual successful seed through the real SAPIEN/Vulkan path, and emit native HDF5 plus decoded rendered video/frame artifacts.

The exact proof remains $NPA_SMOKE_OUTPUT_DIR/robotwin-smoke.json. It must bind the immutable source, asset, and CuRobo revisions; task/config/seed and successful task result; positive action and rendered-frame counts; HDF5/video hashes and sizes; Vulkan renderer evidence; exactly one observed RTX PRO 6000 Blackwell at sm_120; the pod-observed immutable image digest; and exit status zero. Imports, registration, or simulator startup alone are insufficient.

The public YAML contains only sanitized placeholders. Its outer workflow task is CPU-only. The sole future inner accelerator declaration is exactly one STRICT RTXPRO-6000-BLACKWELL-SERVER-EDITION; there is no B200 or fallback route. The manager-authorized source-staging and workload-output destinations remain distinct and never enter public plans, argv, logs, Git, or this PR. RoboTwin submit paths refuse before scheduler, image, network, registry, storage, or GPU effects without genuine authorization and authenticated staged-source byte proof; non-RoboTwin workflows retain their existing behavior.

Six artifact boundaries and licensing

  • Source: RoboTwin is MIT at the pinned revision; its pinned XPolicyLab submodule is Apache-2.0. CuRobo v0.7.8 retains NVIDIA's noncommercial research/evaluation field-of-use restriction. No RoboTwin or CuRobo source or Git metadata is baked or fetched. A future runtime fetch must use the exact provider/revision, verify payload identity, and remain within the recorded bounded noncommercial containerization and technical validation/evaluation statement. No service, derivative, output, commercial, or redistribution right is inferred.
  • Baked runtime: the recipe pins only the official Ubuntu 22.04 linux/amd64 manifest sha256:281c5745f657873d78e5531fc5ba8575f46ab7769b94550ac99543f122679986, immutable Ubuntu snapshot 20260912T000000Z, 75 exact main binary packages and their 75 copyright documents, 57 source packages/177 source artifacts, and a complete-empty zero-artifact Python runtime lock. CUDA, cuDNN, NVIDIA wheels, PyTorch CUDA, CuRobo, SAPIEN, MPLib, Warp, RoboTwin, and their build products are absent.
  • Weights: none are required, fetched, or baked.
  • Data/assets: the pinned RoboTwin2.0 dataset card declares MIT, but aggregate archive member provenance and generated-output treatment remain unresolved. No archive or extracted asset is baked, fetched, or cached.
  • Runtime cache: none exists or was populated. Runtime networking and cache population are disabled. Any future cache requires independently authorized, customer/run-scoped, credential-free, receipt-last atomic handling.
  • Outputs: none were generated and no destination was inferred. Any future JSON, HDF5, MP4, rendered-frame, or log output must use create-only writes to the single manager-authorized destination. Credentials or a writable location are technical mechanisms, not permission to generate, use, serve, or redistribute output.

The four unresolved human decisions remain CUDA delivery/use under the applicable EULA, cuDNN delivery/use under the applicable agreement, CuRobo v0.7.8 service/derivative/output boundaries beyond the bounded noncommercial evaluation, and aggregate RoboTwin asset/output treatment. Runtime fetch, credentials, a private registry, or a passing scanner cannot resolve those decisions.

Fail-closed controls

  • The complete immutable public workflow contract is recognized before RoboTwin special handling; relabelling does not bypass preflight.
  • Direct RoboTwin BYOF/script calls cannot bypass the required CPU outer boundary, including caller-supplied internal transport.
  • Self-certified decision booleans cannot authorize production preflight. A genuine manager receipt and exact gated-access probes are still required.
  • A digest-shaped source coordinate is not byte proof. Authenticated every-path/mode/digest staged-source verification remains mandatory.
  • Validated private context bytes use value-only secret transport, owner-only worker materialization, cleanup, and subprocess-environment scrubbing; private source, authorization, and output values are excluded from public argv, plans, rendered task YAML, logs, journals, transactions, persisted state, and returned submission paths.
  • Handled confidential exceptions are sanitized across their complete cause/context graph and detached before propagation.
  • Authorized output redaction covers the private bootstrap image and every derived repository, registry namespace, and registry-server coordinate.
  • The RoboTwin scanner is path-independent for secret/private-evidence detection and refuses every Phase A candidate before candidate-byte access. It also rejects a completed-looking catalog because a reviewed native exact-content policy is not yet available.

Exact current-head validation

All current-range Python evidence used repository CPython 3.12.14. The reviewed range is base/merge-base c074fccb7836b22f5d19ef4f58ed7e76078e6c5e through head 62f60cc61aad069c21a46aec6427c90e7971cf57: 26 ordinary commits, zero merges, and a 552,530-byte/61-section aggregate diff with SHA-256 447c9a897e0473d850dd1de6d57a5102ff908294a2a57ccf773ae69d4c6e0a81.

  • Current-main PAIDF delta: 41 passed, 0 failed.
  • All 16 solution-changed non-E2E test files: 725 passed, 0 failed.
  • Focused Gitleaks-fingerprint, packaging, and publication repair slice: 378 passed, 0 failed.
  • Workflow validation and planning passed with one CPU outer step, zero outer GPU requests, exactly one future STRICT RTX PRO 6000 request, and zero B200 routes.
  • Ruff, docs drift, tag/readiness consistency, shell syntax, diff hygiene, and confidentiality passed; confidentiality reported 0 raw, 0 dispositioned, and 0 unresolved findings.
  • Exact 26-commit Gitleaks passed with 0 findings and exactly two manager-authorized, receipt-bound public Ubuntu digest fingerprints ignored.
  • Child-isolated pinned Bandit 1.9.4, Zizmor 1.30.0, Trivy 0.74.0, and uv 0.12.5 previously passed hostile fixtures and the canonical source-security comparison on the patch-identical solution bytes: 677 base findings, 677 candidate findings, 0 new findings, and 0 operational failures. The recovery did not replay that unchanged comparison. This remains regression evidence, not a claim of zero inherited security debt.
  • Aggregate scope is 61 changed paths within the unchanged 65-path RoboTwin envelope, with 0 staged, unstaged, untracked, outside-scope, or foreign-primary paths.

Fresh authenticated Claude Code and a distinct ephemeral read-only Codex verifier reviewed the exact base/head/merge-base and all 61 changed paths, 61 diff sections, and 26 ordinary commits. Both passed with 0 blocker/high/major/medium findings and 0 permission denials, writes, or subagents. Claude was provided only Read, Grep, and Glob. Historical denied/incomplete and pre-model review attempts remain preserved and are not counted as passes.

The five nonblocking review notes remain explicit:

  1. The generic image-byte publication regression test is authorized but intentionally untouched until a future publication activation.
  2. A positive native-content-policy path is intentionally unavailable during this fail-closed phase.
  3. The prohibited live E2E harness has a deferred post-submit registry field reference; it cannot run under current gates and is not live evidence.
  4. Complete exception-graph detachment is an intentional, mutation-tested confidentiality tradeoff that discards sanitized traceback chaining.
  5. Several validation functions exceed the repository's preferred 40-line readability limit; this is non-blocking maintainability debt and does not weaken fail-closed behavior.

Deferred gates

No solution source, SDK, runtime, weights, dataset, assets, cache, or output payload was downloaded. No image was built, tagged, pulled, scanned, or pushed. There is no OCI-byte inspection, SBOM, provenance, secret/vulnerability/payload/cache/data/history result, immutable image digest, private-registry pullability proof, anonymous public pull proof, Vulkan result, successful seed, native HDF5, video, or rendered frame.

Future work requires separate authorization and all four human decisions, followed by a complete exact runtime artifact lock; genuine manager-receipt recognition; exact provider/revision/terms access probes; authenticated source and asset bytes; reviewed positive native-content policy; trusted build and complete built-byte evidence; private exact-digest qualification on exactly one STRICT RTX PRO 6000 Blackwell; native policy/output validation; and only then public-development publication, catalog, and anonymous-pull gates. The candidate must never run its renderer on B200. The full 50-task sweep, policy training, and physical-robot deployment remain deferred.

The inherited fixed CRITICAL Perl CVEs in the pre-existing pinned Python slim-Trixie image used by a separate shared scan are not suppressed or waived here. That consuming image/workflow is outside this RoboTwin scope; any current-head CI result is reported separately and truthfully.

Agent-run data collection

Disabled: 0 of 2 required operator settings were present at the latest check. No write/readback verification was possible, no destination was inferred, and no episode was collected.

@timothy-le7
timothy-le7 force-pushed the codex/top5-robotwin branch 3 times, most recently from a1ea37f to da5d6ac Compare September 12, 2026 21:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant